Vulnerabilities > CVE-2024-25634 - Unspecified vulnerability in ALF 2.0M42304
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted request to receive the e-mail log sent by other events. Version 2.0-M4-2402 fixes this issue.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |